Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapRDP connections enabled remotely via Registry Low 2 variations
An attacker may remotely enable RDP connections to a machine by setting the fDenyTSConnections Registry key to 0.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Lateral Movement (TA0008)ATT&CK techniques: Remote Services: Remote Desktop Protocol (T1021.001)Required data: XDR Agent with eXtended Threat Hunting (XTH)Detector tags: Enhanced RDP AnalyticsAttacker's goals: Remotely enable RDP on the host for lateral movement.Investigative actions: Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow. Search for RDP sessions to this host and investigate them for malicious activities.Variations
RDP connections enabled by a remote process via Registry
Low overridden
An attacker may remotely enable RDP connections to a machine by setting the fDenyTSConnections Registry key to 0. overridden
RDP connections enabled remotely via Registry using WinRM
Low overridden
An attacker may remotely enable RDP connections to a machine by setting the fDenyTSConnections Registry key to 0. overridden